IP Library Granted Patent US 7,640,582
Granted Patent B2
US 7,640,582 · App. 10/414,239 · Granted Dec 29, 2009

Clustered filesystem for mix of trusted and untrusted nodes

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,640,582
App. No.
10/414,239
Granted
Dec 29, 2009
Kind
B2
Abstract

A cluster of computer system nodes share direct read/write access to storage devices via a storage area network using a cluster filesystem. At least one trusted metadata server assigns a mandatory access control label as an extended attribute of each filesystem object regardless of whether required by a client node accessing the filesystem object. The mandatory access control label indicates the sensitivity and integrity of the filesystem object and is used by the trusted metadata server(s) to control access to the filesystem object by all client nodes.

Claims (22)

1. A method of operating a cluster of computer system nodes sharing direct read/write access to filesystems administered by at least one trusted metadata server node on storage devices connected to the computer system nodes via a storage area network, comprising:

assigning a mandatory access control label, including a first indication of sensitivity and integrity, as an extended attribute of each filesystem object administered by the at least one trusted metadata server node regardless of whether required by a client node creating the filesystem object;

assigning a second indication of sensitivity and integrity to each node having access to the filesystem; and

permitting access to the filesystem object by any client node only if the second indication of sensitivity and integrity assigned thereto meets criteria defined by the first indication of sensitivity and integrity in the mandatory access control label of the filesystem object;

wherein said assigning uses a default mandatory access control label if a filesystem mandatory access control label is not assigned to the filesystem and a networking mandatory access control label is not assigned to the client node.

2. A method as recited in claim 1 , wherein said assigning of the mandatory access control label uses a filesystem mandatory access control label if previously assigned to the filesystem when the client node requesting access to the filesystem has no mandatory access control label for accessing the filesystem.

3. A method as recited in claim 2 , wherein said assigning of the mandatory access control label uses a networking mandatory access control label if previously assigned to the client node and no filesystem mandatory access control label is assigned to the filesystem.

4. At least one computer readable medium storing at least one program embodying a method of operating a cluster of computer system nodes sharing direct read/write access to filesystems administered by at least one trusted metadata server node on storage devices connected to the computer system nodes via a storage area network, comprising:

assigning a mandatory access control label, including a first indication of sensitivity and integrity, as an extended attribute of each filesystem object administered by the at least one trusted metadata server node regardless of whether required by a client node creating the filesystem object;

assigning a second indication of sensitivity and integrity to each node having access to the filesystem; and

permitting access to the filesystem object by any client node only if the second indication of sensitivity and integrity assigned thereto meets criteria defined by the first indication of sensitivity and integrity in the mandatory access control label of the filesystem object;

wherein said assigning uses a default mandatory access control label if a filesystem mandatory access control label is not assigned to the filesystem and a networking mandatory access control label is not assigned to the client node.

5. At least one computer readable medium as recited in claim 4 , wherein said assigning of the mandatory access control label uses a filesystem mandatory access control label if previously assigned to the filesystem when the client node requesting access to the filesystem has no mandatory access control label for accessing the filesystem.

6. At least one computer readable medium as recited in claim 5 , wherein said assigning of the mandatory access control label uses a networking mandatory access control label if previously assigned to the client node and no filesystem mandatory access control label is assigned to the filesystem.

7. A cluster of computer systems, comprising:

storage devices storing at least one filesystem;

a storage area network coupled to said storage devices;

metadata client nodes coupled to said storage area network; and

at least one trusted metadata server node, coupled to said storage area network, assigning a mandatory access control label, including a first indication of sensitivity and integrity, as an extended attribute of each filesystem object regardless of whether required by a client node accessing the filesystem object, assigning a second indication of sensitivity and integrity to each node having access to the filesystem, and permitting access to the filesystem object by any client node only if the second indication of sensitivity and integrity assigned thereto meets criteria defined by the first indication of sensitivity and integrity in the mandatory access control label of the filesystem object;

wherein said at least one trusted metadata server node uses a default mandatory access control label if a filesystem mandatory access control label is not assigned to the filesystem and a networking mandatory access control label is not assigned to the client node.

8. A cluster of computer systems as recited in claim 7 , wherein said at least one trusted metadata server node uses a filesystem mandatory access control label if previously assigned to the filesystem when the client node requesting access to the filesystem does has no mandatory access control label for accessing the filesystem.

9. A cluster of computer systems as recited in claim 8 , wherein said at least one trusted metadata server node uses a networking mandatory access control label if previously assigned to the client node and no filesystem mandatory access control label is assigned to the filesystem.

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 4, 2017
From: SILICON GRAPHICS INTERNATIONAL CORP.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 044128/0149 →
RELEASE OF SECURITY INTEREST Recorded Nov 2, 2016
From: MORGAN STANLEY SENIOR FUNDING, INC., AS AGENT
To: SILICON GRAPHICS INTERNATIONAL CORP.
Reel/Frame 040545/0362 →
ORDER. . . AUTHORIZING THE SALE OF ALL OR SUBSTANTIALLY ALL OF THE ASSETS OF THE DEBTORS FREE AND CLEAR OF ALL LIENS, CLAIMS, ENCUMBRANCES, AND INTERESTS. Recorded Jul 25, 2016
From: WELLS FARGO FOOTHILL CAPITAL, INC.
To: SILICON GRAPHICS INC.
Reel/Frame 039461/0418 →
ORDER. . .AUTHORIZING THE SALE OF ALL OR SUBSTANTIALLY ALL OF THE ASSETS OF THE DEBTORS FREE AND CLEAR OF ALL LIENS, CLAIMS, ENCUMBRANCES, AND INTERESTS. Recorded Jul 25, 2016
From: MORGAN STANLEY & CO., INCORPORATED
To: SILICON GRAPHICS, INC.
Reel/Frame 039461/0713 →
SECURITY INTEREST Recorded Mar 13, 2015
From: SILICON GRAPHICS INTERNATIONAL CORP.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 035200/0722 →
MERGER Recorded Apr 16, 2014
From: SGI INTERNATIONAL, INC.
To: SILICON GRAPHICS INTERNATIONAL CORP.
Reel/Frame 032692/0938 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2014
From: SILICON GRAPHICS, INC.
To: SILICON GRAPHICS INTERNATIONAL, INC.
Reel/Frame 032693/0001 →
CHANGE OF NAME Recorded Apr 16, 2014
From: SILICON GRAPHICS INTERNATIONAL, INC.
To: SGI INTERNATIONAL, INC.
Reel/Frame 032706/0825 →